Security

FomoPeek iOS App Linked to Malicious Kernel Exploit and Nearly $580,000 in USDT Losses

A malicious iOS app called FomoPeek has been linked to roughly 579,984.34 USDT in stolen funds after researchers said it contained hidden modules capable of escaping Apple’s sandbox, accessing Keychain data and collecting information from other apps.

SlowMist’s threat-intelligence report, published with OKX security researchers, says the app’s versions 1.1 and 1.2 included malicious components named apptrace and libapptracecore. According to the report, those modules enabled remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption and cross-app data collection.

Joint investigation traced the activity onchain

SlowMist said the investigation began after user complaints and was conducted with OKX’s security team. The firm’s analysis identified an attacker address associated with the incident and traced approximately 579,984.34 USDT to that wallet.

The report ties the malicious behavior to specific app versions rather than to the entire product line. It says the harmful components were removed in version 1.3, which followed the affected releases.

On X, SlowMist described the case as a joint investigation with OKX and reiterated that the app contained malicious modules designed to exploit iOS and collect data across apps.

The incident underscores how a mobile app distributed through a major app marketplace can still carry behavior that reaches beyond normal app permissions when kernel-level exploitation is involved. In this case, the reported loss figure comes from onchain tracing rather than from a broader estimate of all possible affected users.